---
id: CVE-2026-15038
title: >-
  The InfiniteWP Client WordPress plugin before 1.13.6 does not properly verify
  the site-connection state and the authenticity of requests to its
  remote-management endpoint on WordPress Multisite installations, allowing
  unauthenticated att…
summary: >-
  The InfiniteWP Client WordPress plugin before 1.13.6 does not properly verify
  the site-connection state and the authenticity of requests to its
  remote-management endpoint on WordPress Multisite installations, allowing
  unauthenticated att…
severity: none
published: '2026-08-09'
updated: '2026-08-09'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-15038'
references:
  - url: 'https://wpscan.com/vulnerability/629d655f-cdb8-4733-81d5-12fa88c32bb6/'
    label: contact@wpscan.com
tags:
  - nvd
  - exploit-available
ingestedAt: '2026-08-09T13:33:29.126Z'
epss: 0.00759
epssPercentile: 0.53438
exploits:
  github: 1
  githubRepos:
    - 'https://github.com/Polosss/By-Poloss..-..CVE-2026-15038-POC'
  checkedAt: '2026-09-27T10:33:39.710Z'
exploitAvailable: true
---

## Overview

The InfiniteWP Client WordPress plugin before 1.13.6 does not properly verify the site-connection state and the authenticity of requests to its remote-management endpoint on WordPress Multisite installations, allowing unauthenticated attackers to bind their own key, hijack an administrator session, and take over the entire network, leading to remote code execution.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
